Login
Sign Up
Woofun AI reports that the Slow Mist security team identified a malicious extension named 'juannegro.solidity' in the TRAE IDE market. Disguised as a legitimate Solidity plugin, this cross-platform malware dropper establishes persistence upon IDE startup and utilizes Ethereum smart contracts to store and retrieve dynamic command-and-control (C2) configurations. Although removed from Open VSX, the extension remained accessible via the TRAE market as of July 18. Attackers can modify C2 endpoints and malicious payloads without republishing the extension. Slow Mist advises users to uninstall the extension immediately and verify system integrity.